Altium Enterprise Server是美国Altium公司的一款本地化数据管理服务器。 Altium Enterprise Server存在安全漏洞,该漏洞源于Vault服务使用硬编码密钥签名文件下载URL,导致未经身份验证的网络攻击者可伪造有效下载签名并读取任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Altium | Altium Enterprise Server | < 8.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Altium | Altium Enterprise Server | 0 ~ 8.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11420 | Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write | |
| CVE-2026-11429 | Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execut | |
| CVE-2026-11431 | Path Traversal in Altium Projects Service Allows Arbitrary File Read | |
| CVE-2026-11423 | Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalati | |
| CVE-2026-11424 | Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information D | |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Wr |
No comments yet